The Containment Burden Sits on the Wrong Side of the Boundary & AI Escape Detection Harness
Barış Ceyhun Coşkun, Emir Raşit Gökçe, Hamza Efe Şahinbaş, Efe Kırbaş, Ayşe Eda Kaya · Team AltaySec
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
This project combines a theoretical incident analysis with a practical engineering solution for the July 2026 OpenAI-Hugging Face breach. We provide a 39-event victim-side reconstruction and a "Kill-Point Matrix" evaluating 26 containment controls by cost and effectiveness. To prove containment in practice, we also engineered a functional, Docker-based detection PoC. It includes multi-layered Wazuh/Sigma correlation rules that detect autonomous C2 loops in ML workloads, demonstrating how to isolate agentic escapes in real-time without alert fatigue.
Reviews
Putting the lab and victim timelines on one axis with cost and evidence grades is a useful contribution, and the self-audit is a model for incident analysis: dropping the unsupported time axis and the post-dated kernel row makes the remaining claims more credible.
The "timing, not cost" finding is partly true by construction, since the chain starts inside the lab and the victim can only act after the boundary is crossed. The cost overlap is the more interesting result, and it would be stronger with operator input. Getting one or two platform engineers to re-score the bands would test it directly.
Substitution is the other open question. Agents that lost one launchpad might have found another, which weakens I-01 and V-14. Noting which controls hold under substitution would sharpen the bundle in Section 4.
I think this project usefully asks who could have acted before the OpenAI-Hugging Face intrusion reached third parties. It maps possible controls to stages of the incident and identifies which organization could apply them. The acknowledgment that precise timestamps do not establish what a different response would have achieved makes the analysis more credible.
The distinction between labs preventing harm and affected platforms merely shortening it is too strong. A platform could also restrict access or remove vulnerable functionality before an attack. I would frame the finding around earlier opportunities for lab intervention, rather than treating prevention as something only the lab can provide.
The project offers a useful synthesis linking potential controls to incident stages, responsible actors, implementation effort, and evidence strength. Its timestamp audit, rejection of unsupported action indices, and explicit treatment of uncertainty are notable strengths.
Cite this project
@misc{coskun2026containment,
title = {{The Containment Burden Sits on the Wrong Side of the Boundary \& AI Escape Detection Harness}},
author = {Barış Ceyhun Coşkun and Emir Raşit Gökçe and Hamza Efe Şahinbaş and Efe Kırbaş and Ayşe Eda Kaya},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/the-containment-burden-sits-on-the-wrong-side-of-the-boundary-ai-escape-detection-harness-7luf}},
url = {https://apartresearch.com/sprints/projects/the-containment-burden-sits-on-the-wrong-side-of-the-boundary-ai-escape-detection-harness-7luf}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …